If your systems store, process or transmit cardholder data, PCI DSS applies — regardless of where your cloud provider's own certification sits. Hosting on a PCI DSS-certified cloud reduces your scope; it doesn't transfer your obligation.
Free readiness call
Thirty minutes, with a specialist who holds a credential in PCI DSS — not a generalist account manager.
SAQ or Report on Compliance (ROC) scoping
Cardholder data environment (CDE) segmentation review
QSA-led assessment (Qualified Security Assessor)
Remediation project management through to attestation
Acquiring bank / payment brand liaison support
Yes. Your provider's certification covers their environment. What you do with the data — how you collect, process and store it — remains your responsibility.
Depends on how card data touches your systems — hosted payment page, direct integration, or in-house processing all point to different SAQ types.
Thirty minutes, free, with someone who holds a credential in the framework you're asking about.
Book a free 30-minute call